Forum     

Go Back   Digit Technology Discussion Forum > Bandwidth Wastage > Chit-Chat
Register FAQ Calendar Mark Forums Read

Chit-Chat General discussions about anything that doesn't fit into the other sections to be had here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 28-06-2007, 12:02 AM   #1 (permalink)
Alpha Geek
 
Join Date: May 2005
Posts: 687
Default lol...Microsoft.co.uk Hacked


Very little time has passed from the last Microsoft defacement (Microsoft Technet), when yesterday Saudi Arabia crackers successfully compromised another Microsoft website: Microsoft.co.uk at the page http://www.microsoft.co.uk/events/ne...x?eventid=8399 .
At the time being, the defacement is still up and running even though not every browser will be capable to show it as too many users are trying now to load the hacker's injected CSS (Cascading Style Sheet) located on an external host (h.1asphhost.com) which now has is suffering slow response time.

By analyzing the HTML source code of the defaced page we can see some "extra" HTML code:

"<link xhref=http://h.1asphost.com/remoter/css.css type=text/css rel=stylesheet>".

The technique used by the attacker to deface Microsoft's page is probably based on a kind of SQL flaw (sql injection). In fact, after a short investigation we noticed how the V2 parameter passed to the PreRegister.aspx script, allows to execute both Cross Site Scripting attacks (www.microsoft.co.uk/events/net/PreRegister.aspx?eventID=p8399&v2="><script>alert(/XSS/)</script>) as well as SQL injection attacks, as you can deduct from the debug error message generated by the application.

Most probably, the attacker exploited the site by means of SQL injection to insert the HTML code "<link xhref=http://h.1asphost.com/remoter/css.css type=text/css rel=stylesheet>" in a field belonging to the table which gets read every time a new page is generated. To discover the name of the table the attacker might have queried the database trying to read the system table "SysObjects" or even the INFORMATION_SCHEMA.TABLES view. We are just speculating here as the DBMS is most probably a MS SQL Server.




VIDEO:

Code:
http://www.megaupload.com/?d=F9U1RBWB
__________________
Any use of the collective descriptions and shared knowledge from any of my posts are at the sole discretion of the reader.I am not responsible for what you do with it.
rajas700 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 28-06-2007, 12:13 AM   #2 (permalink)
The Transcendental
 
Join Date: Dec 2005
Location: Nutopia
Posts: 285
Default Re: lol...Microsoft.co.uk Hacked

^ ain't it ironical the screenies on safari.
*don't flame me, i'm no fanboy*
__________________
:::::::::: When freedom is outlawed, only outlaws will have freedom ::::::::::
..:: Free Radical ::.. is offline  
Old 28-06-2007, 01:15 AM   #3 (permalink)
 Macboy
 
goobimama's Avatar
 
Join Date: Sep 2004
Location: Goa
Posts: 4,486
Default Re: lol...Microsoft.co.uk Hacked

Hey! I was gonna go with a safari based comment!

But I must say it feels good when one is hacked. One of my sites was hacked by some hax0r....felt good. Felt like living in the real world or something...
__________________
I'm like a bird... :)
goobimama is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
mac hacked ? vignesh Technology News 1 30-04-2007 04:18 PM
Have I been hacked? nagarjun_424 QnA (read only) 18 19-04-2007 07:35 PM
Hacked!!!!!!!!!!! tanush_89 QnA (read only) 12 22-01-2007 05:40 PM
IE 6 Hacked, opera also hacked, plz help!!!! Andyiz Software Q&A 6 08-11-2005 04:11 PM
help msn id hacked??????? deadmanrulz QnA (read only) 1 21-05-2005 11:43 AM

 
Latest Threads
- by kool
- by Who
- by Tenida
- by kool

Advertisement




All times are GMT +5.5. The time now is 12:25 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2